Executive brief
Ekushey Project Manager CRM, a tool used for managing business projects and customer support, is vulnerable to a security flaw in its ticketing system. An authenticated customer can submit a support ticket reply containing malicious code that will automatically run in the browser of a staff member or administrator when they view the ticket. This could allow an attacker to perform unauthorized actions on behalf of the administrator or access sensitive management data.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in Ekushey Project Manager CRM through version 5.0 due to improper neutralization of input in the 'Reply Ticket' field. An authenticated attacker with 'Client' privileges can inject malicious JavaScript payloads into a support ticket. When a 'Staff' or 'Administrator' user subsequently views the Support Ticket detail page or summary table, the payload executes within their browser session. This can lead to session hijacking, unauthorized administrative actions, or data exfiltration. The vulnerability is tracked as CWE-79 and requires user interaction (viewing the ticket) to trigger.
Affected products
- Creativeitem Ekushey Project Manager CRM through 5.0
Timeline
- 2026-07-25: disclosed: Researcher disclosure by Aaron Amran Bin Amiruddin
- 2026-07-27: advisory: NVD publication date